Under the DPDP Act 2023, personal data may be processed either with the Data Principal's explicit consent (Section 6) or for certain 'legitimate uses' (Section 7) such as state functions, legal compliance, medical emergencies, or employment. Unlike GDPR's legitimate interest, India's DPDP Act does not allow a broad balancing test — legitimate use is a closed list. Choosing the wrong lawful basis exposes organisations to penalties up to ₹250 crore.
DPDP consent legitimate use India — Complete DPDP Compliance Guide
DPDP Act 2023 allows data processing either with consent or for 'legitimate uses' — specific scenarios where consent is not required. Understanding the distinction is critical for compliance.
Quick AnswerLegitimate uses under DPDP include: state functions, medical emergencies, employment obligations, court functions, and public safety. Most commercial data processing requires consent — legitimate use cannot be stretched to avoid consent obligations.
DPDP Compliance Checklist
Consent is the primary basis — default to consent for all commercial data processing
Legitimate use 1: Voluntary data for a specific purpose (individual clearly expects processing)
Legitimate use 2: State/government functions — no consent required for legitimate government processing
Legitimate use 3: Medical emergencies where consent cannot be obtained
Legitimate use 4: Epidemic or public health emergency responses
Legitimate use 5: Employment-related processing (but only for stated employment purposes)
Legitimate use 6: Court or legal authority functions
Do not use 'legitimate use' as a shortcut to avoid consent — the Board will scrutinise this
Document your chosen legal basis for each processing activity
Review basis periodically — legitimate use may expire when the specific purpose ends
Download Full Compliance Guide (Free)
Get the complete sector-specific checklist, risk areas, and 30-day action plan — delivered to your inbox.
Frequently Asked Questions
Can companies use 'legitimate interest' like under GDPR?+
DPDP does not have a 'legitimate interest' balancing test like GDPR. The legitimate uses in DPDP are specific and exhaustive — if your processing doesn't fit, you need consent.
Can employers process employee data without consent?+
Employment-related processing falls under legitimate use — but only for purposes directly related to employment. Using employee data for marketing without consent is not covered by employment legitimate use.
What happens if an organisation claims legitimate use incorrectly?+
If the Data Protection Board finds an organisation incorrectly relied on legitimate use to avoid obtaining consent, this constitutes a violation — potentially attracting significant penalties.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.